acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Designs and documents structured incident response playbooks that define step-by-step procedures for specific
$ npx -y skills add Mikaru0Mystic/sectinel --skill building-incident-response-playbook --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/building-incident-response-playbookContext preview
The summary Claude sees to decide when to auto-load this skill.
Designs and documents structured incident response playbooks that define step-by-step procedures for specific
name: building-incident-response-playbook description: 'Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design. ' domain: cybersecurity subdomain: incident-response tags: - IR-playbook - runbook - NIST-800-61 - SOAR-integration - response-procedures mitre_attack: - T1190 - T1566 - T1078 version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - RS.MA-01 - RS.MA-02 - RS.AN-03 - RC.RP-01
**Do not use** for one-time ad hoc investigations; playbooks are reusable procedure documents, not case-specific reports.
Define the specific scenario the playbook will address:
Common playbook types:
Priority Playbooks (build first): 1. Ransomware incident response 2. Phishing/credential compromise 3. Business email compromise 4. Malware infection 5. Data breach/exfiltration 6. DDoS attack 7. Insider threat 8. Account takeover 9. Web application compromise 10. Cloud infrastructure compromise
Every playbook should follow a consistent structure:
PLAYBOOK TEMPLATE ━━━━━━━━━━━━━━━━ 1. Playbook Metadata - Name, version, owner, last review date - Trigger conditions - Severity criteria 2. RACI Matrix - Who is Responsible, Accountable, Consulted, Informed for each step 3. Detection & Triage - How the incident is detected - Initial triage checklist - Severity classification criteria 4. Containment - Short-term containment actions - Long-term containment actions - Evidence preservation requirements 5. Eradication - Root cause identification - Malware/threat removal steps - Verification procedures 6. Recovery - System restoration steps - Validation criteria - Monitoring requirements post-recovery 7. Post-Incident - Lessons learned meeting trigger - Report template - Detection improvement actions 8. Communication - Internal notification matrix - External notification requirements (regulators, customers, law enforcement) - Status update cadence 9. Appendices - Tool-specific procedures - Contact lists - Evidence collection checklists
Define clear decision points with binary outcomes:
Detection Alert Received ├── Is the alert a true positive? │ ├── YES → Classify severity │ │ ├── P1 (Critical) → Page incident commander, begin containment immediately │ │ ├── P2 (High) → Notify IR lead, begin investigation within 30 min │ │ ├── P3 (Medium) → Queue for investigation within 4 hours │ │ └── P4 (Low) → Document and investigate within 24 hours │ └── NO → Document as false positive, tune detection rule └── Cannot determine → Escalate to Tier 2 for deeper analysis
Escalation triggers:
Write tool-specific instructions for each step (not generic guidance):
CONTAINMENT - Endpoint Isolation via CrowdStrike:
1. Open Falcon Console > Hosts > Search for affected hostname
2. Click on the host > Host Details
3. Click "Contain Host" button in upper right
4. Confirm isolation (host will only communicate with CrowdStrike cloud)
5. Document containment action in incident ticket with timestamp
6. Verify containment: Host should show "Contained" status badge
CONTAINMENT - Block C2 Domain at DNS:
1. SSH to DNS server: ssh admin@dns-primary.corp.local
2. Add to block zone: echo "zone evil.com { type master; file /etc/bind/db.sinkhole; };" >> /etc/bind/named.conf.local
3. Reload DNS: rndc reload
4. Verify: dig @dns-primary evil.com (should resolve to sinkhole IP 10.0.0.99)
5. Document blocked domain in incident ticketConvert manual playbook steps into automated workflows:
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative